CRITICAL

CVE-2023-27855

CVSS v3

9.8

CRITICAL

EPSS Score

67.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. The attacker could overwrite existing executable files with attacker-controlled, malicious contents, potentially causing remote code execution.

Technical details

Published
3/22/2023

Frequently asked questions

What is CVE-2023-27855?

In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. The attacker could overwrite existing executable files with attacker-controlled, malicious contents, potentially causing remote code execution.

Is CVE-2023-27855 actively exploited?

Active exploitation of CVE-2023-27855 has not been confirmed. The EPSS score is 67.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-27855?

CVE-2023-27855 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-27855 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.